Mozilla Foundation Security Advisory 2008-47

Information stealing via local shortcut files

Announced

November 12, 2008

Reporter

Liu Die Yu

Impact

Moderate

Products

Firefox, SeaMonkey

Fixed in

Firefox 2.0.0.18

Firefox 3.0.4

SeaMonkey 1.1.13

Description

Security researcher Liu Die Yu of
TopsecTianRongXin reported that locally saved .url shortcut files
could be used to read information stored in the local cache. An
attacker could use this vulnerability to steal information from a
victim's browser cache if they were able to get the victim to download
two separate files, a .url shortcut and a HTML file. Given the
relative complexity of this attack, the severity of the issue was
determined to be moderate.

Workaround

Disable JavaScript until a version containing these fixes can be
installed.